CVE-2026-96587: hardcoded plaintext credentials in Viidure Dashcam Android Application

Anyone who extracts credentials baked into the Dashcam Android Application can obtain full control over the product’s cloud storage and so read, alter, or remove critical files such as firmware and application binaries. CVE-2026-96587 covers permanent plaintext cloud credentials compiled into the app. The flaw affects branch 3.x — 3.3.1.260403 and earlier — and can be exploited without logging in or convincing a user to act if an attacker can get hold of the app package or a device image containing the embedded secrets.

Published Updated Source: CVE Program, NVD

CVSS 3.1
10CRITICAL
EPSS
n/a
CWE
CWE-798
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High priority: this is an unauthenticated, high-impact exposure because recovered plaintext credentials provide complete storage access; immediately rotate credentials and tighten storage access while awaiting a vendor fix.

What is CVE-2026-96587?

Anyone who extracts credentials baked into the Dashcam Android Application can obtain full control over the product’s cloud storage and so read, alter, or remove critical files such as firmware and application binaries. CVE-2026-96587 covers permanent plaintext cloud credentials compiled into the app. The flaw affects branch 3.x — 3.3.1.260403 and earlier — and can be exploited without logging in or convincing a user to act if an attacker can get hold of the app package or a device image containing the embedded secrets. The weakness is classified as CWE-798 (Use of Hard-coded Credentials).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Viidure Dashcam Android Application are affected?

BRANCHAFFECTEDFIXED
3.x3.3.1.260403 and earlier

Is CVE-2026-96587 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-96587

  1. Rotate any cloud credentials that may be present in Dashcam Android Application builds immediately.
  2. Limit cloud storage accounts to the minimum necessary privileges and restrict access by IP, network, and service account.
  3. Enable and review storage access logs for unexpected activity and investigate anomalies promptly.
  4. Request vendor remediation and remove hardcoded credentials from application builds in future releases.

Frequently asked questions

Is CVE-2026-96587 being actively exploited?

There are no public reports of active exploitation of CVE-2026-96587 as of 2026-09-30.

Which Dashcam Android Application versions are affected by CVE-2026-96587?

The vulnerability affects Dashcam Android Application branch 3.x, specifically version 3.3.1.260403 and earlier.

Is there a patch for CVE-2026-96587?

No fixed versions are listed in the available facts; implement mitigations such as credential rotation and access restrictions until the vendor provides a patch.

Does CVE-2026-96587 require authentication?

No, exploitation does not require authentication once an attacker extracts the embedded plaintext credentials from the app or a device image.

References